SilverStripe 2.3.7 - Security Release

12 views
Skip to first unread message

Ingo Schommer

unread,
Mar 17, 2010, 8:14:07 PM3/17/10
to SilverStripe Release Announcements
We have a new release of SilverStripe available: 2.3.7

This is a recommended security release, fixing the following issues:
* Privilege escalation for authenticated CMS users
* Unauthenticated remote file deletion of index.php, which affects
URL routing without rewriting (this is not an issue for the majority
of environments with mod_rewrite enabled, but has been secured either
way).

Download here: http://www.silverstripe.org/assets/downloads/SilverStripe-v2.3.7.tar.gz
Post bug reports here: http://open.silverstripe.com
Changelog: http://open.silverstripe.org/wiki/ChangeLog/2.3.7

Thanks,
Ingo Schommer

Reply all
Reply to author
Forward
0 new messages